US11750608B2ActiveUtilityA1

Assisted third-party password authentication

Assignee: CAPITAL ONE SERVICES LLCPriority: Jun 8, 2020Filed: Apr 11, 2022Granted: Sep 5, 2023
Est. expiryJun 8, 2040(~13.9 yrs left)· nominal 20-yr term from priority
H04L 63/0884H04L 9/3073H04L 63/083H04L 63/166H04L 63/0815H04L 63/0807
70
PatentIndex Score
0
Cited by
5
References
20
Claims

Abstract

Disclosed herein are system, method, and apparatus for assisted third-party password authentication. The method performed at a client device includes creating a secure connection from an inline frame associated with a first application on the client device to an authorization server for accessing a second application. The method includes identifying, by the inline frame, one or more events that represent inputs for a user authorization credential, and proxying, by the inline frame, the identified one or more events to the authorization server using the secure connection. The method includes receiving an authorization code from the authorization server in response to the proxying. The method includes redirecting, by the inline frame, the authorization code to the application on the client device. The method includes transmitting, from the client device to the authorization server, the authorization code to receive an access token for accessing the second application.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
       1. A method, comprising:
 creating a secure connection from an inline frame associated with a first application on a client device to an authorization server for accessing a second application; 
 identifying, by the inline frame, one or more events that represent inputs for a user authorization credential; 
 proxying, by the inline frame, the identified one or more events to the authorization server using the secure connection; 
 redirecting, by the inline frame, an authorization code to the first application on the client device; 
 transmitting, to the authorization server, the authorization code to receive an access token for accessing a second application; 
 generating, by the inline frame, a form for receiving the user authorization credential; and 
 updating the form with a graphical symbol to avoid interrogation of a document object model (DOM) element associated with the form; 
 inserting the inline frame in the first application according to a restricted access policy; and 
 closing the inline frame upon receiving the access token from the authorization server. 
 
     
     
       2. The method of  claim 1 , further comprising:
 inserting the inline frame in the first application based on an agreement between the first application and the second application according to the restricted access policy. 
 
     
     
       3. The method of  claim 1 , further comprising:
 encrypting the one or more events proxied to the authorization server using a public-private key pair. 
 
     
     
       4. The method of  claim 1 , wherein creating the secure connection comprises:
 establishing a connection between the inline frame and the authorization server using a secure connection protocol from a group comprising transport layer security (TLS), secure socket layer (SSL), secure socket shell (SSH), and hypertext transfer protocol over SSL/TLS (HTTPS). 
 
     
     
       5. The method of  claim 1 , wherein the first application is a first hypertext markup language (HTML) page and the second application is a second HTML page, and wherein the second HTML page is different from the first HTML page. 
     
     
       6. The method of  claim 1 , wherein the access token is valid for a predetermined time interval. 
     
     
       7. The method of  claim 1 , further comprising providing an address of the second application at the first application. 
     
     
       8. A system, comprising:
 a memory; and 
 a processor coupled to the memory, the processor configured to: 
 transmit a request to an inline frame associated with a first application to render a form configured to receive authorization credential information for accessing a second application; 
 verify the authorization credential information upon receiving the authorization credential information in response to the inline frame receiving or listening for a key event; 
 transmit an authorization code to the inline frame in response to authorizing the authorization credential information; and 
 transmit an access token to the first application via the inline frame, wherein the first application uses the access code to access the second application. 
 
     
     
       9. The system of  claim 8 , wherein the first application is a first hypertext markup language (HTML) page and the second application is a second HTML page, and wherein the second HTML page is different from the first HTML page. 
     
     
       10. The system of  claim 8 , wherein the inline frame is generated in the first application based on an agreement between the first application and the second application according to a restricted access policy. 
     
     
       11. The system of  claim 8 , wherein a connection between a server and inline frame is formed using a secure connection protocol from a group comprising transport layer security (TLS), secure socket layer (SSL), secure socket shell (SSH), and hypertext transfer protocol over SSL/TLS (HTTPS). 
     
     
       12. The system of  claim 8 , wherein the access token is valid for a predetermined time interval. 
     
     
       13. The system of  claim 8 , wherein the inline frame includes an HTML tag, IP address, or a fully qualified domain name (FQDN) of a server. 
     
     
       14. The system of  claim 8 , wherein the key event is encrypted using a public-private key-pair. 
     
     
       15. A non-transitory computer-readable medium having instructions stored thereon that, when executed by at least one computing device, cause the at least one computing device to perform operations comprising:
 creating a secure connection from an inline frame associated with a first application on a client device to an authorization server for accessing a second application; 
 identifying, by the inline frame, one or more events that represent inputs for a user authorization credential; 
 proxying, by the inline frame, the identified one or more events to the authorization server using the secure connection; 
 redirecting, by the inline frame, an authorization code to the first application on the client device; 
 transmitting, to the authorization server, the authorization code to receive an access token for accessing the second application; 
 generating, by the inline frame, a form for receiving the user authorization credential; and 
 updating the form with a graphical symbol to avoid interrogation of a document object model (DOM) element associated with the form; 
 inserting the inline frame in the first application according to a restricted access policy; and 
 closing the inline frame upon receiving the access token from the authorization server. 
 
     
     
       16. The non-transitory computer-readable medium of  claim 14 , wherein the operations further comprise:
 inserting the inline frame in the first application based on an agreement between the first application and the second application according to the restricted access policy. 
 
     
     
       17. The non-transitory computer-readable medium of  claim 14 , wherein the operations further comprise:
 encrypting the one or more events proxied to the authorization server using a public-private key pair. 
 
     
     
       18. The non-transitory computer-readable medium of  claim 14 , wherein creating the secure connection comprises:
 establishing a connection between the inline frame and the authorization server using a secure connection protocol from a group comprising transport layer security (TLS), secure socket layer (SSL), secure socket shell (SSH), and hypertext transfer protocol over SSL/TLS (HTTPS). 
 
     
     
       19. The non-transitory computer-readable medium of  claim 14 , wherein the first application is a first hypertext markup language (HTML) page and the second application is a second HTML page, and wherein the second HTML page is different from the first HTML page. 
     
     
       20. The non-transitory computer-readable medium of  claim 14 , wherein the access token is valid for a predetermined time interval.

Join the waitlist — get patent alerts

Track US11750608B2 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.